← All legal documents

Data Processing Agreement

Version 2026-05-22 · Effective: Pending

Draft document

This document is being finalised ahead of general availability. The section structure below is provisional and not yet binding. Final wording will be published before customer onboarding.

How NutriCare processes personal and health information on a facility’s behalf. Incorporated into the Terms of Service.

Roles

The customer is the controlling entity for resident data; NutriCare processes that data only on the customer’s documented instructions.

Scope and nature of processing

The categories of data, the categories of data subject (residents, staff, family), and the purposes of processing.

Sensitive information and consent

Resident health information is sensitive information under the Privacy Act. The customer warrants it has the authority and consents required to provide that information to NutriCare, including for AI features.

Sub-processors

The published sub-processor list is incorporated by reference. NutriCare gives notice before adding a new sub-processor.

Cross-border disclosure

Most data resides in Australia. AI features may disclose data to Anthropic in the United States; this is controlled by an organisation-level opt-out.

Security measures

The technical and organisational security measures NutriCare applies, drawn from its security and compliance register.

Data breach notification

NutriCare notifies the customer without undue delay of a data breach affecting its data, so the customer can meet its Notifiable Data Breaches obligations.

Data subject requests

NutriCare assists the customer in responding to resident access and correction requests.

Return and deletion of data

Export and deletion of customer data on termination, accounting for aged-care record-retention requirements.

Audit

The customer’s rights to review NutriCare’s security posture.

Questions about this document? Contact hello@day-zero.com.au.